Microsoft’s September Patch Tuesday tackles nearly 1,000 vulnerabilities
Microsoft’s September security update covers Windows and other products, with independent reports differing on the exact number of fixes.

Microsoft has published its September 2026 Security Update Guide, covering security fixes across Windows and other products. Independent reports describe the release as one of the company’s largest monthly patch batches, but they disagree on the exact total: Guru3D reports 974 vulnerabilities, while TechPowerUp reports 999.
Both reports say Windows accounts for 723 fixes. Guru3D also identifies fixes across Office, SQL Server, Azure, Exchange Server, SharePoint Server, Skype for Business and developer tools.
Guru3D reports that two Windows privilege-escalation vulnerabilities — CVE-2026-81963 and CVE-2026-85880 — are listed as actively exploited. Microsoft’s detailed advisory is delivered through a JavaScript application, so the exact severity breakdown could not be read back through the available retrieval path.
The conflicting totals mean the headline should not pretend there is one settled number until Microsoft’s underlying advisory data is checked directly. No claim about zero-days or attack details is being made here.
Why you should care
Patch Tuesday is not exciting until an unpatched machine becomes somebody else’s foothold. Windows users and administrators should treat this as a prompt to check their normal update process, while remembering that the final list of affected products and urgency belongs to Microsoft’s own advisory.
Our opinion
The number is eye-catching, but the useful message is less dramatic: update your systems and do not build a security plan around a headline count. Microsoft needs to make the underlying advisory easier to inspect, because “974 or 999” is not the sort of ambiguity administrators should have to resolve through third-party articles.